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, Abstract 

£\) | We explain the mechanism of the quantum speed-up - quantum algo- 

rithms requiring fewer computation steps than their classical equivalent - 
for a family of algorithms. Bob chooses a function and gives to Alice the 
black box that computes it. Alice, without knowing Bob's choice, should 
find a character of the function (e. g. its period) by computing its value for 
different arguments. There is naturally correlation between Bob's choice 
and the solution found by Alice. We show that, in quantum algorithms, 

■ this correlation becomes quantum. This highlights an overlooked mea- 

surement problem: sharing between two measurements the determination 
of correlated (thus redundant) measurement outcomes. All is like Alice, 
by reading the solution at the end of the algorithm, contributed to the 
initial choice of Bob, for half of it in quantum superposition for all the 
possible ways of taking this half. This contribution, back evolved to be- 

yj-^ ' fore running the algorithm, where Bob's choice is located, becomes Alice 

, knowing in advance half of this choice. The quantum algorithm is the 

■ quantum superposition of all the possible ways of taking half of Bob's 

choice and, given the advanced knowledge of it, classically computing the 
missing half. This yields a speed-up with respect to the classical case 
where, initially, Bob's choice is completely unknown to Alice. 



1 Foreword 



Our explanation of the speed-up relies on the interplay between the unitary 
part of the quantum algorithm and the initial an final measurement operations. 
Because of the interdisciplinary character of the work, we spend a few lines to 
introduce the language of quantum computation. 

An algorithm is the computation that solves a problem. Quantum computa- 
tion is the implementation of the algorithm at a fundamental physical level. A 
quantum algorithm yields a speed-up when it requires fewer computation steps 
than its classical equivalent, sometimes demonstrably fewer than classically pos- 
sible. 

Wc focus on a family of quantum algorithms that comprises the major speed- 
ups. Bob, the problem setter, chooses a function out of a known set of functions 
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and gives to Alice a black box that computes it. Alice, without knowing Bob's 
choice, should find a character of the function by computing its value for different 
arguments. 

The essential things of a quantum computation process are: 

1. The register, which contains a number or a quantum superposition thereof. 

The register's initial state is the input of the computation; e. g.: | ( 1 00) + 1 01) + 1 10) + |11)). 

2. The (reversible) computation, a unitary transformation U that sends the 
input into the output - the result of the computation or the solution of 
the problem. E. g.: U\ (|00) + |01) + 1 10) + 1 11>) = ^ (|00) + |11)). 

3. The initial measurement, required to prepare the register in the desired 
initial state. In particular, we are interested in the preparation of the 
choice of the problem on the part of Bob. 

4. The final measurement, performed by Alice in the output state of the 
register to read the solution of the problem. 

The seminal speed-up was discovered by Deutsch [1] in 1985. The subsequent 
speed-ups can be seen as ingenious mathematical extrapolations of Deutsch's 
algorithm. We provide an example of speed-up. Given a chest of four drawers. 
Bob hides a ball in one of the drawers, Alice should locate the ball by opening 
different drawers. Classically, to be sure of locating the ball, Alice should plan 
to open three drawers. Quantally, one drawer. This is the simplest instance of 
Grover's [2] quantum search algorithm. 

In 2001, Grover [3] called for a two- line explanation of the reason for the 
speed-up, one that does not enter into the mathematical detail of each quantum 
algorithm. It can be said that quantum computer science prevailingly explored 
the opposite direction, focusing on the mathematical gear of quantum algorithms 
and trying to unify it. In the context of the present work, it is important to 
note that such attempts mostly focus on the unitary transformation part of 
quantum algorithms. Apropos of this, it should be noted that many quantum 
algorithms are unitary transformations starting and ending with a sharp state of 
the register. This might have provided the feeling that the speed-up is essentially 
deterministic in character. 

In 2009, Gross, Flammia, and Eisert [4] claimed that the exact reason for 
the quantum speed-up had never been explained. 

Our explanation of the quantum speed-up, relying on the interplay between 
the unitary and the non- unitary part of the quantum algorithm, goes against the 
aforesaid trend. It also shows that the apparent determinism of the quantum 
speed-up is a sort of "visual illusion". 

2 Extended summary 

Our explanation of the speed-up starts with the obvious observation that there is 
correlation between the problem and its solution - e. g., one to one correlation 
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between the drawer number initially chosen by Bob and the drawer number 
eventually found by Alice. The explanation can be divided in three steps. The 
first step (Section 3.f ) is showing that, in quantum algorithms, this correlation 
becomes quantum. 

We divide the register into sub-registers - for short "registers" as well. In 
the four drawer case, we have a two-quantum-bit (qubit) register B, under the 
control of Bob, and a two-qubit register A, under the control of Alice. Let b be 
the number of the drawer with the ball, a that of the drawer opened by Alice. 
Bob writes his choice of the value of b, say b = 00, in register B. Alice writes 
the number of the drawer she wants to open in register A. Reading the content 
of a register amounts to measuring a corresponding observable. We call B the 
content of register B, of eigenvalues b <G {00,01, 10, 11}, and A the content of 
register A, of eigenvalues a € {00, 01, 10, 11}. We note that A and B commute. 

We assume that register B is initially in a maximally mixed state - so that 
the value of b is completely undetermined. In fact we want to examine the 
entire process that leads to the determination of Bob's choice. 

In order to prepare register B with the desired value of b, Bob should mea- 
sure B in the maximally mixed state of register B. He obtains an eigenvalue 
at random, say b = 01. Then he changes the corresponding eigenstate into 
the desired one, by applying to B a suitable permutation of the basis vectors, 
namely a unitary transformation Ub- At this point Alice runs the unitary part 
of the quantum algorithm, which eventually writes the solution in register A. 
Alice acquires the solution a = b = 00 by measuring A. 

A crucial point of our argument is noting that there is quantum correlation 
between the outcome of the initial measurement of B and that of the final 
measurement of A. In fact, quantum correlation concerns repetitions of the 
same quantum experiment. Therefore, from the standpoint of it, the unitary 
transformation Ub should be considered fixed. The fact that Bob chooses Ub 
to always obtain the choice 00, independently of the outcome of measuring B, 
belongs to a different film. Looking only the latter film originates the aforesaid 
"visual illusion" - the apparent determinism of quantum computation and the 
speed-up. 

Instead, the quantum speed up essentially relies on (non-deterministic) quan- 
tum correlation. As the fixed permutation of a randomly selected value of b, 
Bob's choice b = 00 should be considered random. Up to the fixed permuta- 
tion Ub, there is quantum correlation between Bob's choice b = 00 and Alice's 
reading of the solution a = b = 00. 

This can be best seen by virtually deferring the measurement of B at the 
end of the unitary part of the quantum algorithm - see Section 3.1 for details. 
The state of the two registers, before the measurement of either B or A, is: 

\ (e*° |00> B |00) A + e* 1 |01> B |01) A + e** |10> B |10) A + c^ |11> B |11) J . 

(1) 

The ifi are independent random phases, each with uniform distribution in [0, 2tt]. 
We use the random-phase representation of a density operator to keep the ket 
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vector representation of the quantum algorithm. The density operator is the 
average over all ipi of the product of the ket by the bra: (\tp) The von 

Neumann entropy of this state is two bits. Measuring B or A projects |T|) on: 

|00) B |00) A . (2) 

Back evolving the projection of ([1} on @, by the inverse of the time forward 
unitary transformation, restores the projection of the initial state of register B 
on b = 01. 

Let us sum up the situation. We are dealing with two measurements - 
Bob's measurement of B and Alice's measurement of A - whose outcomes are 
completely (as in the four drawers case) or partly (more in general) correlated. 

It is of course unquestionable that quantum measurement determines an 
eigenvalue of the measured observable, but when there are two measurements 
for two redundant or partly redundant eigenvalues, what do we have to say? 

Interestingly, while quantum correlation has been the source of an enormous 
amount of research, the problem of fairly sharing between two measurements 
the determination of two completely (or partly) correlated eigenvalues - thus 
completely (or partly) redundant with one another - has been overlooked. 

To analyze this problem, it is useful to introduce the reduced density oper- 
ators of registers B and A in state ([T]), respectively pb and pa- The usual way 
of solving this problem is thinking that the measurement performed first takes 
the lion's share. If we assume that the measurement of B is performed first, we 
ascribe to it: the zeroing of the entropy of ps and the zeroing (or reduction) 
of the entropy of pa- If we assume that the measurement of A is performed 
first, we ascribe to it: the zeroing of the entropy of pa and the zeroing (or re- 
duction) of the entropy of ps- We call these two perspectives "the lion's share 
perspectives" . 

The second step of our explanation (Section 3.2) relies on performing this 
sharing in a way that is not affected by the order of the two measurement, or 
the fact that the two measurement are performed simultaneously. 

This is justified by the following consideration. Determination means reduc- 
tion of entropy, due to the projection - associated with quantum measurement 
- of a state of higher entropy on one of lower entropy . However, while quan- 
tum measurements are localized in time, the corresponding projections are not, 
they can be back evolved along the unitary part of the quantum algorithm by 
the inverse of the time-forward unitary transformation. Therefore, there is no 
reason to ascribe the lion's share to the measurement performed first, not to 
speak of the fact that the two measurements can be simultaneous. 

To present ends, it suffices to focus on sharing - between Alice's and Bob's 
measurements - the projection on Bob's choice. The physical meaning of such a 
sharing is of course to be found in the notion of partial measurement of B. For 
example, we can think of measuring B , the content of the left cell of register 
B, in state ((T|). A-proiori, this yields either bo = or &o = 1 (bo being the 
left bit of b). In present assumptions, the overall measurement of B projects on 
Bob's choice b = 00, we are in fact discussing how to share this projection. This 
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naturally implies the assumption that the measurement of Bo yields 60 = 0. 

Summing up, we should divide the projection on Bob's choice into two pro- 
jections. Each projection is associated with a partial measurement of B, with 
outcome post-selected to match with Bob's choice. One projection should be 
ascribed to Bob's measurement of B, the other to Alice's measurement of A. 

We define our sharing rule as follows. To start with, we get rid of all re- 
dundancy by resorting to Occam's razor, or law of parsimony. In Newton's 
formulation [5], it states 11 We are to admit no more causes of natural things 
than such that are both true and sufficient to explain their appearances" . This 
law of parsimony requires (i) that the two projections completely determine 
Bob's choice without any over-determination, namely without projecting twice 
on the same information. 

It is reasonable to require that the two projections keep the common qualities 
of the two lion's share perspectives. By this we mean that we require that each 
projection "properly" reduces the entropies of both pb and pa- Moreover, from 
a quantitative standpoint, we require that entropy reductions are shared in a way 
that mirrors the symmetry of the measurement situation. For example, in the 
four drawer case - Eq. (pj - this implies that the sharing of entropy reductions 
between Alice's and Bob's measurements is fifty-fifty. This is condition (ii). 

Eventually, we require (iii) that the sharing of the projection on Bob's choice 
is done in all the possible ways, compatible with the former conditions, in quan- 
tum superposition. 

The above conditions (i) through (iii) are enough to univocally solve the 
"sharing problem" in all the quantum algorithms examined in this paper. 

The third step of our explanation (Section 3.3) is showing that Alice's con- 
tribution, back evolved to before running the algorithm (by the inverse of the 
time- forward unitary transformation), where Bob's choice is positioned, becomes 
Alice knowing half of Bob's choice in advance, in all possible ways in quantum 
superposition. 

Correspondingly, the quantum algorithm turns out to be the quantum su- 
perposition of all the possible ways of taking half of Bob's choice and, given the 
advanced knowledge of this half, classically computing the missing half. This of 
course yields a speed-up with respect to the classical case where Bob's choice, 
initially, is completely unknown to Alice. 

This explanation of the quantum speed-up has two main implications: 

(I) The quantum speed-up comes from comparing two classical algorithms, 
with and without advanced knowledge of half of Bob's choice. This implication 
is thus a tool for finding the achievable speed-ups - a central problem in quan- 
tum computation. Moreover, this problem is brought to an entirely classical 
framework, an important simplification. 

(II) It shows that the quantum speed-up hosts a special causality loop. In 
quantum search, Alice knows in advance 50% of the bits that specify the so- 
lution, in all possible ways in quantum superposition, and, given the advanced 
knowledge of these bits, reaches the solution with fewer computation steps. 
Each individual history contains a causality loop; in the four drawer case, Alice 
knows in advance that the ball is in one of two drawers, and this before opening 
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any drawer. Thus, opening any one of these two drawers allows Alice to locate 
the ball. This would be impossible if there were only one isolated history. It 
becomes possible because, in the superposition of all histories, all the draw- 
ers are opened and there is cross-talk between histories because of quantum 
interference. 

In the following Sections, first we develop our argument in detail for Grover's 
algorithm, then we show that it holds unaltered for the very diverse quantum 
algorithms that yield an exponential speed up. 

With respect to Ref. [6] , we bring to a fundamental physical level the prob- 
lem of sharing between Alice's and Bob's measurements the determination of 
Bob's choice. This allows us to extend, to Deutsch and Jozsa's algorithm, 
Simon's algorithm and the Abelian hidden subgroup algorithm, the detailed 
explanation of the mechanism of the speed-up already developed for Grover's 
algorithm. 

3 Grover's algorithm 

Section 3.1 highlights quantum problem-solution correlation in Grover's algo- 
rithm. In Sections 3.2 through 3.4, we develop the notion of advanced knowl- 
edge. 

3.1 Quantum problem-solution correlation 

We formalize the four drawer example. Bob chooses a two-bit number b = b^bi; 
Alice should find the value of b by computing the Kronecker function 5 (b, a) 
for various values of a = a^ai. The value of 6 (b, a) is 1 if a = b, otherwise, 
which tells Alice whether the ball is in drawer a. 

Usually, the value of b chosen by Bob is thought to be hard-wired inside 
the black box that computes <5 (b, a). To highlight quantum correlation, we 
add to the usual description of the quantum algorithm an imaginary quantum 
register B that contains the hard-wired valueQ- In Section 3.3, this imaginary 
register will serve to represent the usual quantum algorithm (with the hard- 
wired value) "with respect" to the observer Alice in the sense of relational 
quantum mechanics. 

In view of this representation, we should consider the entire process of de- 
termination of the value of b. Thus, we assume that register B is initially in a 
maximally mixed state. Register A contains the value of a tried by Alice, the 
one-qubit register V (like "value") is meant to contain the result of the compu- 
tation of d (b, a), modulo 2 added to its former content for logical reversibility. 

1 Wc have taken the expression "imaginary register" from Ref. [7], which hilights the 
problem-solution symmetry of Grover's and the phase estimation algorithms. 
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The two latter registers are initially prepared as required by Grover's algorithm: 

IV) = ^= (e^° |00) B + e^ \01) B + e^ |10) B + e*» |11) B ) 

(\00) A + \01) A + \W) A + \11) A ) (\0) v - . (3) 

To prepare B, Bob needs to know its state. To this end, he measures B in 
state ([3]). This randomly selects a value of b, say 01, projecting ([3]) on: 

P a IV) = |01> B (\00) A + \01) A + \1Q) A + |11) J (|0> v - |l) y ) , (4) 

we denote projection operators by the letter P. The two-bit entropy of the 
quantum state goes to zero with the determination of the value of b. 

Then he applies to register B a permutation of the values of b - a unitary 
transformation £/ B - that changes the randomly selected value of b into the 
desired one, say 00: 

UbP q |V) = |00) B (\00) A + \Q1) A + \1Q) A + \ll) A ) (\0) v - \l) v ) . (5) 

We note that Bob can choose the desired value off-line in any way, for example 
random with whatever probability distribution. 

The reversible computation of S (b, a), represented by the unitary transfor- 
mation Uf (/ like "function evaluation"), sends §5§ into: 



U f U B P a |V) = Jj= |0Q) B (- \00) A + \Q1) A + \10) A + \ll) A ) (|0) v - \l) v ). (6) 

A non-computational operation, the rotation Ua of the measurement basis of 
register A (the so called "inversion about the mean") yields: 

U A U f U B P a |V) = i |00) B \00) A (|0) v - \l) v ) . (7) 

In (J7]) , register A contains the solution of the problem - the value of b chosen 
by Bob. Alice acquires it by measuring A, which by the way leaves state ([7]) 
unaltered. 

Of course, there is a one-to-one correlation between the value of b chosen 
by Bob and the solution found by Alice. Up to the permutation introduced 
by Ub, this corresponds to the quantum correlation between the outcome of 
measuring B in ^ and that of measuring A in As anticipated in the 

Extended summary, from the standpoint of quantum correlation, which concerns 
repetitions of the same quantum experiment, the permutation U B should be 
considered fixed (the fact that Bob chooses it to obtain the desired value of b 
belongs to a different film). 

With a fixed U B , all is like the value of b chosen by Bob was randomly 
selected - this value becomes the fixed permutation of the randomly selected 
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value. Moreover, we can virtually defer the measurement of B at the end of the 
algorithm (in Section 3.3, we will show that this yields the quantum algorithm 
"relativized" to the observer Alice). The previous input-output sequence of ket 
vectors becomes: 

|V) = ^= (e***" |00) B + e^ \01) B + e^ |10) B + e*» |n) s ) 

(\00) A + \01) A + \W) A + \11) A ) (\0) v - |l) v ) , (8) 
U B |V) = |V) (9) 



U f U B |V) 



u A u f u B 



\00) K (" l°°>Jf + l 01 >* + l 10 )x + l n >x) + 



e'** |01) K (100). - |01) 



|io) K (|oo> 



'x 



01 



|10>x 
|10>x 



in; 
in; 



e^ |11) K (|00) x + |0lf x + |10) x - \l\) x ) 



1 



(e^|00) B |00) A +e^|01) B |01) A 
|l)y), 

P^U A U f U B |V) = -j= |00) B |00) A (|0) v - 



2V2 

(|Q)v- 



|10)j 



(|o) v -|i) v ), 

(10) 

|10) A + e^|ll) fl |ll) A ) 
(11) 
(12) 



In sending ([SJ into ©, J/s should permute the suffixes of the <pi. We do not 
take this into account since it is irrelevant, given that the ipi are independent 
random phases. The computation of 6 (b, a), namely Uf, maximally entangles 
the content of register B with that of register A. In (fT0|) , four orthogonal states 
of B, each a value of b, are correlated with four orthogonal states of A, which 
means that the information about the value of b has propagated to register A. 
The rotation of the measurement basis of A makes this information readable: 
entanglement also becomes correlation between measurement outcomes. We can 
see why Bob's measurement can be virtually deferred at the end: the projection 
of (fTTj) on (fT2|) , back evolved by U B l/jU A , becomes the projection of ([3]) on (|4]). 

Thinking that all measurements are performed in the maximally entangled 
state (fTTj) makes it more clear that the value of b is randomly selected by either 
Bob's or Alice's measurement; by the way, since A and B commute, the order 
of these two measurements (which can also be simultaneous) in state (fTTj) is 
irrelevant. Either measurement projects state (|11[) on the solution eigenstate 
(fT2|) , where both registers contain the selected value of b; correspondingly, the 
two-bit entropy of the quantum state goes to zero. 

In view of what will follow, it is useful to introduce the reduced density 
operator (in the random phase representation) of register B in state (jTTJ) : 



Pb = 2 (e^° |00) B + |01) B + e^ |10) B + e*** |11) B ) 



(13) 
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Incidentally, we note that ps is the same in states flSJ) through (fTTj). up to the 
irrelevant permutation of random phases; the algorithm is in fact the identity 
on the reduced density operator of the control register. The projection of state 
(fTTj) on the solution eigenstate (|12p implies of course the projection of p B on 
|00) B ; we will also say "on b G {00}". By the way, considering also pa would 
lead to completely redundant considerations. 

3.2 Sharing the projection on Bob's choice 

Given that now the value of b can be determined by measuring either A in 
state (jlip or B in the same or any former state, we share the projection of 
state (jlip on (|T2"j) into two projections, one ascribed to Alice's measurement the 
other to Bob's, in such a way that conditions (i) through (iii) of the sharing rule 
described in the Extended summary are satisfied. 

In the case of Grover's algorithm, the (in general) n bits that specify the 
value of b are independently selected in a random way (as the fixed permutation 
of a similar selection). Thus, condition (i) states that the projection onp of these 
bits (0 < p < n) should be ascribed to Alice's measurement, that on the other 
n — p bits to Bob's. This also means ascribing an entropy reduction of p bits 
to Alice's measurements, of n — p bits to Bob's. Thus, condition (ii) implies 
p = n/2. 

As also anticipated in the Extended summary, the physical meaning of shar- 
ing the projection on the value of b is related to the notion of partial measure- 
ment of B. For example, going back to n = 2, we can think of measuring B a , 
the content of the left cell of register B, in state (jXTJ) . This yields either bo = 
or b = 1, projecting pB on either i (e IVo |00) B + |01) B ) or, respectively, 

(e z ^ 2 |10) B + e lVi |11) B ). In the present assumption, the overall measure- 
ment of B projects ps on b G {00}, we are in fact discussing how to share 
this projection. This naturally implies the assumption that the measurement of 
B projects p B on -4- (e ilfi0 |00) s + e 1 ^ 1 |01) B ); we also say "on b G {00,01}". 

Under the same assumption, measuring B±, the content of the right cell of B, 
projects on b e {00, 10}. There is still one partial measurement that yields 
one bit of information about the value of b, that of Bx, the exclusive or of 
the contents of the two cells. Measuring Bx projects - always under the same 
assumption - on b G {00,11}. Summing up, a possible way of dividing the 
projection of ps on b G {00} is to split it into any two of the following three 
projections, on: b G {00, 01}, b G {00, 10}, and b G {00, 11}. In the four draw- 
ers visualization, this means of course pairing drawer 00 with another drawer in 
all possible ways. 

This example is not fortuitous. In fact, it is the only way of sharing (be- 
tween Alice's and Bob's measurements) the projection on b G {00} that satisfies 
conditions (i) and (ii). One can readily see that the measurement of any pair 
of observables among Bq, B\, and Bx, selects a value of b without projecting 
twice on any bit of this value. Furthermore, the entropy drop associated with 
either one of the two measurements is the same. One can also see that there is 
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no other way of satisfying the above conditions; condition (iii) will be addressed 
further below. 

We provide an example for n = 4. The projection on, say, b g {0000} can 
be shared, say, in the projection on b g {0000,0001,0010,0011} and that on 
b e {0000,0100, 1000, 1100}. The former projection corresponds to measuring 
B and B\ and finding 6 = &i = 0, the latter to measuring B 2 and B 3 and and 
finding 62 = ^3 = 0. 

3.3 Advanced knowledge 

We show that ascribing to Alice part of Bob's choice, implies that she knows in 
advance, before running the algorithm, that part of the choice. 

To this end, we introduce the notion of relativized quantum algorithm, in 
the sense of relational quantum mechanics [8] . We note that states (jHj) through 
(fl~2j) are the original quantum algorithm - we mean states ([5]) through ([7]) (to be 
counted twice, before and after the measurement of A) — but with the quantum 
state relativized to the observer Alice. By definition, initially Alice does not 
know the content of register B. To her, register B is in a maximally mixed 
state even if Bob has already chosen the value of b. The two-bit entropy of 
state © represents Alice's complete ignorance of the value of b. When Alice 
measures A at the end of the algorithm, the quantum state (fTTj) is projected on 
the solution eigenstate (TT2j) . This projection is random to Alice, it is actually 
on the value of b chosen by Bob. The entropy of the quantum state goes to zero 
and Alice acquires full knowledge of the value of b. Thus, the entropy of the 
relativized quantum state gauges Alice's ignorance of the value of b throughout 
the execution of the algorithm. 

With this result, we go back to our aim. We work on an example. We share 
the projection of state (jlll) on (fT2j) , namely the selection of b = 00, by ascribing 
to Alice's measurement the projection of dTTT) on: 

\ (e^° |00) fl |00) A + e^ |01) B |01} A ) (|0) v - \l) v ) , (14) 

namely the selection of ciq = bo = 0. This selection is like it was randomly 
generated at the time and location of Alice's measurement. To become a con- 
tribution to Bob's choice (itself the fixed permutation of a randomly generated 
value), it must propagate to the time and location of Bob's choice - in particular 
to before running the algorithm and immediately after applying Ub- Therefore, 
we should back evolve the corresponding projection by applying U* B U\u\ to the 
two ends of it, namely to states (fTTj) and (fTTj) . This yields the projection of the 
initial state (f9j) - or, identically, ([8]) - on: 

\ (e*° |00) B + e^ |01) B ) (|00) A + |01) A + |10) A + (|0) v - \\) v ) . (15) 

The entropy of the initial state of register B is halved. Since this entropy 
represents Alice's initial ignorance of Bob's choice, this means that Alice, before 
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running the algorithm, knows n/2 of the bits of Bob's choice, here one bit - in 
fact 60 = 0. 

We are at the level of elementary logical operations, where knowing means 
doing. Alice knows half of Bob's choice (the value of bo) by acting like she knew 
it, namely by using it to identify classically the missing half (the value of b\) 
with a single computation of 5 (b, a). Correspondingly, as we showed in [6], the 
quantum algorithm is the superposition of all the possible ways of taking one 
bit of information about Bob's choice and, given the advanced knowledge of this 
bit, classically identifying the missing bit with a single computation of 5 (b, a) - 
see also Section 3.4. This explains the speed-up from three to one computation. 
This also satisfies condition (iii) of our sharing rule, namely that the projection 
on the value of b is shared between Alice's and Bob's measurements in all 
possible ways (compatibly with the other conditions) in quantum superposition. 

This explanation of the mechanism of the speed-up generalizes to b any 
number of bits - see Ref. [6] . 

3.4 Superposition of classical computation histories 

We show in which sense the quantum algorithm can be seen as a superpo- 
sition of classical computations. As we have seen, in the assumption that 
Bob's choice is b = 00, Alice's advanced knowledge can be: b e {00,01}, 
or b e {00, 10}, or b e {00, 11}. We start with the first possibility. Given 
the advanced knowledge of b £ {00, 01}, to identify the value of b Alice should 
compute 5 (b,a) for either a = 00 or a = 01. Let us assume it is for a = 00. 
The outcome of the computation is S = 1. This originates two classical com- 
putation histories, depending on whether the initial state of register V is |0)y 
or \l) v . Each classical history is represented as a sequence of sharp quantum 
states, as follows. The initial state of history 1 is e llpo \00) B \00) A \0) v (the ket 
|00) B means that b = 00, the ket |00) ^ that the input of the computation 
of S is a = 00); the state after the computation of S is e lipo \00) B \00) A \l) v 
(the result of the computation is modulo 2 added to the former content of 
register V). We are using the history phases that reconstruct the quantum 
algorithm: our present aim is to show that the quantum algorithm is a super- 
position of classical computation historiefl In history 2, the states before/after 
the computation of S are - e^° |00) B \00) A |l) v -> -e^° \00) B \00} A \0) v . In 
the case that Alice computes 6 (b, a) for a = 01 instead, she obtains S — 
0, which of course tells her again that b = 00. This originates other two 
histories. History 3: e^ n |00> s |01> A |0) v -> |00) B |01) A \0) v ; history 4: 
-e lVo |00) B \Ql) A \l) v -> -e^° |00) B 101)^ \l) v . We develop in a similar way 
the other possibilities, also for all the possible choices of the value of b. The 
computation step of Grover's algorithm, namely the transformation of §§§ into 
(fT0|) , is the superposition of all these histories. 

By the way, this also explains quantum parallel computation. In fact, in the 
initial state of the quantum algorithm and in the superposition of all classical 

2 History phases can also be found from scratch by maximizing entanglement - see Ref. [6]. 
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computation histories, each \ij) B is multiplied by: 



^-j= (|00> A + |01) A + |10) A + (|0) v - |l) v ) , (16) 

as one can readily check. 

As one can see, the computation step we are dealing with is the identity on 
the reduced density operator of register B (the control register) and entangles 
this register with register A (the target register). The information contained in 
B leaks to A - see state (fT0|) . At this point we perform a non-computational 
step: a suitable rotation Ua of the basis of register A (the so called "inversion 
about the mean"). This branches each history into four histories; such branches 
interfere with one another to give state (fTTj) . Entanglement also becomes corre- 
lation between the possible measurement outcomes. By the way, this implicitly 
defines Ua (inversion about the mean) as the rotation of the basis of register A 
that maximizes correlation between possible measurement outcomes. 

Summing up, Grover's algorithm can be decomposed into a superposition of 
histories, which start from Alice's advanced knowledge and whose computational 
part is entirely classical. This result also applies to n > 2, by iterating the 
sequence of the two steps (computational and non computational) O (2"' 2 ) 
times. By the way, this means a "quadratic" speed-up with respect to a classical 
algorithm that requires O (2 n ) computations. 



4 Deutsch&Jozsa's algorithm 

In Deutsch&Jozsa's [9] algorithm, the set of functions known to both Bob and 
Alice is all the constant and "balanced" functions (with an even number of 
zeroes and ones) /b : {0, 1}" —> {0, 1}. Array (fT7| gives this set for n — 2. The 
string b = 6o, 6i, &2»-i is both the suffix and the table of the function - the 
sequence of function values for increasing values of the argument. Specifying 
the choice of the function by means of the table of the function simplifies the 
discussion. 



a 


/oooo ( a ) 


/mi (a) 


/oon (a) 


/lioo (a) 


/oioi (a) 


/ioio (a) 


/ono (a) 


Aooi (a) 


00 





1 





1 





1 





1 


01 





1 





1 


1 





1 





10 





1 


1 








1 


1 
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1 


1 





1 








1 



(17) 



Alice should find whether the function selected by Bob is balanced or con- 
stant by computing /b (a) = / (b, a) for appropriate values of a. In the classical 
case this requires, in the worst number of computations of / (b, a) ex- 

ponential in n; in the quantum case one computation. 

We give the relativized states before and after the unitary part of the algo- 
rithm, namely V r A.Uf {Ub, Uf, and Ua play the same role as before but are of 
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course specific to the algorithm): 



U b \i/>) = I (c tva |0000) B + c llpl \mi) B + e lV2 |0011} B + c^ 3 |1100) B + ...) 
8 

(|00) A + |01) A + |10) A + \U) A ) (\0) v - \l) v ) (18) 

U A U f U B |</>) = \ [(e^° |0000) B - |1111} B ) \00) A + (e^ |0011} B - c^ 3 |1100) B ) \10} A 

(|Q)v-|l)v)- ( 19 ) 

The entangled state (fH)|) is reached with a single computation of / (b,a). Mea- 
suring A in (JTHJ) yields the solution: all zeros if the function is constant, not so 
if it is balanced. 

This time entanglement is a-symmetric and we should consider the reduced 
density operators of both registers B and A in state (fH))) : 

p B = -A= (e' Vo |0000) B + e iipi |1111) B + e iV2 |0011) B + e^ 3 |1100) B + ...) , 
2V2 

(20) 

PA = \ (e^> \Q0) A + \01) A + |10) B + e^ 3 , (21) 

the "&i are independent random phases with uniform distribution in [0, 27r] as 
well. This time the entropies of p B and pa are different, 3 bits and 2 bits 
respectively. Incidentally, we note that p B remains unaltered throughout the 
unitary transformation XJ aU$Ub- 

We lay down the two lion's share perspectives. If we assume that the mea- 
surement of B is performed first, we ascribe to it: the zeroing of the entropy of 
p B and the zeroing of the entropy of pa ■ If we assume that the measurement of 
A is performed first, we ascribe to it: the zeroing of the entropy of pa and the 
reduction of the entropy of p B . 

Condition (ii) of the sharing rule becomes that each one of "the two projec- 
tions" (as defined in the sharing rule) properly reduces both entropies. This is 
enough to univocally solve the sharing problem. 

To perform the sharing, in the first place we should identify the "elementary" 
partial projections. A natural choice is considering the projections associated 
with measuring Bq, B\, ... , of course selecting the measurement outcomes 
that match with Bob's choice. To fix ideas, we assume that Bob's choice is 
b = 0011. This means considering the projections on the single bits of the bit 
string b = 0011 or, in equivalent terms, on the single rows of the table of /b - see 
the third column of array (|17[) . As we will see, this provides sufficient resolution 
to build the history superposition picture of the quantum algorithm; considering 
also Boolean functions of the bit string 0011 would generate repeated histories 
here. 

Summing up, we should select two shares of the table of the function (the 
projection on one should be ascribed to Alice's measurement, that on the other 
to Bob's) in such a way that, together, they project on the value of b without 
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over-projecting on any part of it and, individually, reduce the entropies of both 
p B and pa- 

This implies that no share contains different values of the function or, if all 
the values are the same, more than 50% of the rows. Otherwise, the projection 
on that share would already tell that the function is balanced, or constant. 
For the no over-projection condition, this would mean ascribing to only one 
projection the entire reduction of the entropy of pa, against condition (ii). 

Conditions (i) and (ii) are satisfied if the two shares of Bob's choice b = 0011 
are respectively fb (00) = 0, fb (01) = and fb (10) = 1, fb (11) = 1 - see array 
(TTT|) . One can easily check that any deviation from this sharing violates the 
aforesaid conditions. For example, if the two shares were instead fb (00) = 
and /b(ll) = 1, projecting on them would not determine Bob's choice, thus 
violating condition (i). If they were fb (00) = 0, fb (01) = and fb (11) = 1, 
this would determine Bob's choice, but the projection on the latter share would 
not reduce the entropy of pa, thus violating condition (ii). Etc. We call either 
one of the two shares of the table a good half table. 

Incidentally, nothing a-priori requires that we split the entire table of the 
function into two shares. In the quantum part of Shor's [10] factorization al- 
gorithm - finding the period R of a periodic function - conditions (i) and (ii) 
dictate that one share of the table is a set of R consecutive rows, the other 
share a similar set with arguments displaced by a multiple of R (the two sets 
should be taken in all possible ways in quantum superposition). Splitting the 
entire table into two shares, if the domain of the function spans more than two 
periods, would imply over-projection. 

Back to Deutsch and Jozsa's algorithm, besides Alice's contribution to Bob's 
choice, a good half table represents Alice's advanced knowledge of this choice. 
In fact, since ps remains unaltered throughout the unitary part of the quantum 
algorithm, also the projection of pb on a good half table (on the superposition 
of the values of b that match with it) remains unaltered. At the end of the 
relativized quantum algorithm, this projection represents Alice's contribution 
to Bob's choice. At the beginning, it changes Alice's complete ignorance of 
Bob's choice into knowledge of the good half table. 

It is immediate to check that the quantum algorithm requires the number 
of function evaluations of a classical algorithm that knows in advance a good 
half table. In fact, the value of b, and thus the solution, are always identified 
by computing fb (a) for only one value of a (anyone) outside the half table - 
see array (117j) . Thus, both the quantum algorithm and the advanced knowledge 
classical algorithm require just one function evaluation. 

Now we go to the history superposition picture. It is convenient to group the 
histories with the same value of b. Starting with b = 0011, we assume that Al- 
ice's advanced knowledge is the good half table / (b, 00) = 0, / (b, 01) = 0. As 
this is common to b = 0000 and b = 0011, in order to find the value of b and thus 
the character of the function, Alice should perform function evaluation for cither 
a = 10 or a = 11. We assume it is for a = 10. Since we are under the assump- 
tion b = 0011, the result of the computation is 1. This originates two classical 
computation histories, each consisting of a state before and one after function 
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evaluation. History 1: e^ 2 |0011) B \10) A |0) v -> e iV2 |0011) B \10) A \l) v ; his- 
tory 2: -e iV2 |0011) B |10) A -> -e^ 2 |0011} B |10) A |0) y . If she performs 
function evaluation for a = 11 instead, this originates other two histories, etc. 

In this way, in the state before function evaluation, the value of b is mul- 
tiplied by the superposition of all the possible combinations of values of a and 
contents of register V. This explains quantum parallel computation. Performing 
a single computation of / (b, a) entangles registers B and A. 

Until now we have seen the function evaluation stage of the quantum algo- 
rithm. Before going further, it can be useful to summarize the overall picture. 
Alice knows in advance half of the value of b. In order to find the solution, a 
function of b, she should identify the entire value of b, by performing function 
evaluation for only one value of a (anyone) outside the half table. This is done 
in all possible ways in quantum superposition. Function evaluation is the iden- 
tity on pb] it entangles registers B and A. Information contained in the control 
register B leaks to the target register A. Eventually, applying the Hadamard 
transform to register A yields state (fTTJf : entanglement also becomes correlation 
between the possible measurement outcomes. 

By the way, the fact that Alice, in each individual history, knows half of the 
value of b and computes the missing half in order to find the solution, agrees 
with the fact that Alice cannot know the precise value of b by measuring A in 
state (|19[) . In fact this depends on the special form of state (fT!))) . where each 
eigenstate of A multiplies the superposition of two eigenstates of B; this form 
emerges in the very superposition of the individual histories. 

It is easy to see that the present analysis, like the notion of good-half-table, 
holds unaltered for n > 2. 

5 Simon's and the hidden subgroup algorithms 

In Simon's [11] algorithm, the set of functions is all the /b : {0, 1}™ — > {0, l}™" 1 
such that /b (a) = /b (c) if and only ifa = cora = c© h( b ' ; © denotes bitwise 
modulo 2 addition; the bit string h^ h \ depending on b and belonging to {0, 1}™ 
excluded the all zeroes string, is a sort of period of the function. Array (|22|) 
gives the set of functions for n = 2. The bit string b is both the suffix and the 
table of the function. Since h( b ) © h( b ) = 0, each value of the function appears 
exactly twice in the table, thus 50% of the rows plus one surely identify h( b ). 





h(oon) = oi 


h (1100) = Q1 


h(oioi) = 10 


h (1010) = 1Q 


h (0110) = n 


h (1001) = u 


a 


/ooii (a) 


/lioo (a) 


/oioi (a) 


/ioio (a) 


/ono (a) 


Jiooi (a) 


00 





1 





1 





1 


01 





1 


1 





1 





10 


1 








1 


1 





11 


1 





1 








1 



(22) 

Bob selects a value of b. Alice's problem is finding the value of h( b ), "hid- 
den" in /b(a), by computing /b (a) = /(b, a) for different values of a. In 
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present knowledge, a classical algorithm requires a number of computations of 
/ (b, a) exponential in n. The quantum algorithm solves the hard part of this 
problem, namely finding a string orthogona , with one computation 

of / (b, a). There are 2 ra_1 such strings. Running the quantum algorithm yields 
one of these strings at random (see further below). The quantum algorithm 
is iterated until finding n — 1 different strings. This allows us to find h^ 3 - 1 by 
solving a system of modulo 2 linear equations. 

We give the relativized states before and after the unitary part of the algo- 
rithm: 



U B \i>) = ^7= (c ivo |0011) B + c ivi \1W0) B + e^ 2 |0101) B + e^ 3 |1010) 



1 

(|00) A + |01) A + |10) A + |11)J|0) V . (23) 



tj n u l/a _ J_ J (e iV0 |0011) B + \1W0) B ) [(\00) A + \W) A ) \0) v + (\00) A - \10) A ) \l) v ] 
m ~ 2V6 I +(^ 2 |0101) fl + e^ |ioio) B ) [(\00) A + \01) A ) \0) v + (\00) A - \01) A ) \l) v ] 4 

(24) 

In (|23p . register V is prepared in the all zeros string (just one zero for 
n = 2). State (|2"4"| is reached with a single computation of / (b, a). In (|24p . for 
each value of b, register A (no matter the content of V) hosts even weighted 
superpositions of the 2™ _1 strings orthogonal to h( b ). By measuring A 

in this state, Alice obtains at random one of the Sj . Then we iterate the 
"right part" of the algorithm (preparation of registers A and V, computation 
of / (b, a), and measurement of A) until obtaining n — 1 different . 

Let pb and pa be the reduced density operators of respectively B and A 
in state (|24|) . We lay down the two lion's share perspectives in the assumption 
that we always throw away the projections on |00)^, which do not reduce the 
entropy of either ps or p A (tell nothing about the value of b or the solution). If 
we assume that the measurement of B is performed first, we ascribe to it: the 
zeroing of the entropy of pb and the reduction (zeroing in the case n = 2) of the 
entropy of pa- If we assume that the measurement of A is performed first, we 
ascribe to it: the zeroing of the entropy of pa and the reduction of the entropy 
of pb- This can readily be checked by looking at the form of state (|2"4"1) . 

Condition (ii) of the sharing rule becomes that each one of "the two pro- 
jections" properly reduces both entropies. The analysis of the former section - 
about how to share the projection on the value of b between Alice's and Bob's 
measurements - still holds. Now half of Bob's choice is any half table that does 
not contain the same value of the function twice, which would already specify 
the value of h( b ) and thus of all the . 

We check that the quantum algorithm requires the number of function eval- 
uations of a classical algorithm that knows in advance a good half table. In 
fact, the solution is always identified by computing / (b, a) for only one value of 
a (anyone) outside the half table. The new value of the function is necessarily 



3 The modulo 2 addition of the bits of the bitwise product of the two strings should be zero. 
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a value already present in the half table, which identifies h.( b ) and thus all the 
sj b '. Thus, both the quantum algorithm and the advanced knowledge classical 
algorithm require just one function evaluation. 

We go to the history superposition picture. Let us assume that Bob choose 
b = 0011. Alice's advanced knowledge is either / (b, 01) = 0, / (b, 10) = 1 
or / (b, 00) = 0,/(b, 11) = 1. Let us start with the former possibility. As 
this half table is common to b = 0011 and b = 1010, in order to find the 
value of b and thus the character of the function, Alice should perform func- 
tion evaluation for either a = 00 or a = 11. We assume that it is for a = 00. 
The result of the computation is 0. This originates two classical computa- 
tion histories, each consisting of two states, before and after function evalu- 
ation. History 1: e^° |0011) B \00) A |0) y e^ |0011) B \00) A \0) v ; history 2: 
-e i( f° |0011) B \00} A \l) v -e ivo |0011) B \00) A |l) v . If she performs function 
evaluation for a = 11 instead, the result of the computation is 1. This origi- 
nates other two histories, etc. The sum of all histories is the function evaluation 
stage of the quantum algorithm. After function evaluation, we should apply the 
Hadamard transform to register A. Each history branches into four histories; 
branches interfere with one another to yield state (fM|) . 

The present analysis holds unaltered for n > 2. It also applies to the gen- 
eralized Simon's problem and to the Abelian hidden subgroup problem. In fact 
the corresponding algorithms are essentially the same as the algorithm that 
solves Simon's problem. In the hidden subgroup problem, the set of functions 
/b : G —> W map a group G to some finite set W with the property that there 
exists some subgroup S < G such that for any a, c e G, /b ( a ) = /b (c) if and 
only a + S = c + S. The problem is to find the hidden subgroup S by com- 
puting /b (a) for various values of a. Now, a large variety of problems solvable 
with a quantum speed-up can be re-formulated in terms of the hidden subgroup 
problem [12, 13]. Among these we find: the seminal Deutsch's problem, finding 
orders, finding the period of a function (thus the problem solved by the quantum 
part of Shor's factorization algorithm), discrete logarithms in any group, hidden 
linear functions, self shift equivalent polynomials, Abelian stabilizer problem, 
graph automorphism problem. 

6 Summary and conclusions 

We summarize and position the results obtained. The present explanation of 
the speed-up: 

(i) Relies on solving a fundamental measurement problem: how to share 
between redundant measurements the determination of correlated eigenvalues. 

(ii) Shows that the apparent determinism of quantum algorithms is a visual 
illusion. 

(iii) Applies to both quadratic and exponential speed-ups. The unifications 
achieved so far, which focus on the unitary part of the quantum algorithm, do 
not capture both kinds of speed-up. 



17 



(iv) Highlights the existence of a common scheme for the family of quan- 
tum algorithms examined: (a) Given the advanced knowledge of half of Bob's 
choice, Alice finds the missing half through function evaluations; each function 
evaluation is the identity on the reduced density operator of the control register 
B and increases the entanglement between this register and the target register 
A; information about Bob's choice flows from the former to the latter register 
- this is of course a "character" of the function chosen by Bob. (b) By chang- 
ing the basis of the target register after each function evaluation, entanglement 
also becomes correlation between the possible measurement outcomes (the ap- 
plication, after function evaluation, of the "inversion about the mean", or the 
Hadamard transform, or the quantum Fourier transform in the case of Shor's 
algorithm, maximizes this correlation) . (c) Steps (a) and (b) should be repeated 
the number of times required to classically find the missing half of Bob's choice. 

(v) Allows us to derive new quantum algorithms. Given a set of functions, 
we go through steps (a), (b), and (c), and see what is the character of the 
function obtained. Then we design the problem (finding that character of the 
function) around this result. Ref. [6] provides an example in point. 

(vi) Provides a tool for ascertaining the quantum speed-up achievable in 
solving a problem - a central issue in quantum computation. The speed-up 
comes from comparing two classical algorithms, with and without advanced 
knowledge of half of Bob's choice. 

(vii) Highlights the existence of special causality loops. Each individual his- 
tory contains such a loop: Alice knowing in advance half of Bob's choice without 
computing it. This is possible because the missing computation is performed in 
other histories and quantum interference provides cross-talk between histories. 
The causality loop remains fully there in the superposition of all histories. 

Possible future work is trying and extend the present explanation to other 
quantum algorithms and further investigating what the explanation means at a 
fundamental physical level. One could expect cross fertilization between these 
two prospects. 
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